Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-34298


Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.


Published

2025-10-30T22:15:49.257

Last Modified

2025-11-06T16:27:12.660

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-281

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nagios log_server < 2024 Yes
Application nagios log_server 2024 Yes
Application nagios log_server 2024 Yes
Application nagios log_server 2024 Yes
Application nagios log_server 2024 Yes
Application nagios log_server 2024 Yes
Application nagios log_server 2024 Yes
Application nagios log_server 2024 Yes

References